DNN
cpe:2.3:a:dnnsoftware:dotnetnuke:*:*:*:*:*:*:*
- >= 9.0.0, <= 9.13.9
- >= 10.0.0, < 10.2.0
A stored cross-site scripting vulnerability has been identified in DNN (DotNetNuke) versions 9.0.0 prior to 9.13.10 and 10.0.0 prior to 10.2.0. This vulnerability allows extensions to write rich text in log notes, which can include scripts that execute in the PersonaBar when the notes are displayed.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the log notes.
Users can upgrade to DNN versions 9.13.10 or 10.2.0, both of which include the necessary fix.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.